Malware is constantly evolving, in constant flux, with new trends and techniques emerging on a monthly basis.
The Malwarebytes team has been constantly monitoring exploit kits lately and how they could change the future.

WHAT ARE EXPLOIT KITS?
Exploit kits or EKs are web-based applications hosted by cyber criminals. EK operators typically purchase web traffic from malvertising campaigns or botnet operators.
Traffic from malicious ads or hacked websites is sent to the so-called “EK gate” where the operator selects only users with specific browsers or Adobe Flash versions and redirects these potential targets to a “landing page.”
This is where EKs "run" a vulnerable program and use a browser or Flash vulnerability to "plant" malware on a user's computer.

EKS – FILELESS ATTACKS
But in a study published last week, Malwarebytes say that EK operators are changing their tactics.
Instead of relying on removing the malware to disk and then executing it, at least three of the nine active EKs operating today use fileless attacks.
A fileless attack is based on "loading" malicious code into the computer's RAM, without leaving traces on the disk.
Exploit kits exploit this technique, including Magnitude, Underminer, and Purple Fox.

BYE-BYE FLASH!
But that wasn't the only trend Malwarebytes spotted. The company says that more and more exploit kits are taking advantage of Flash Player.
The main reason is that Adobe Flash 's market share has declined in recent years, reaching below 8% in Google Chrome,
